Re: [kitten] [IANA #748877] please review SASL-SCRAM-256

Simon Josefsson <simon@josefsson.org> Thu, 10 April 2014 22:18 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EAE011A0316 for <kitten@ietfa.amsl.com>; Thu, 10 Apr 2014 15:18:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.348
X-Spam-Level:
X-Spam-Status: No, score=0.348 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, HELO_EQ_SE=0.35, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FLOkAZja7I5l for <kitten@ietfa.amsl.com>; Thu, 10 Apr 2014 15:18:13 -0700 (PDT)
Received: from duva.sjd.se (duva.sjd.se [IPv6:2001:9b0:1:1702::100]) by ietfa.amsl.com (Postfix) with ESMTP id C16DC1A031E for <kitten@ietf.org>; Thu, 10 Apr 2014 15:18:12 -0700 (PDT)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by duva.sjd.se (8.14.4/8.14.4/Debian-4) with ESMTP id s3AMI0WW021139 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT) for <kitten@ietf.org>; Fri, 11 Apr 2014 00:18:02 +0200
Date: Fri, 11 Apr 2014 00:17:59 +0200
From: Simon Josefsson <simon@josefsson.org>
To: kitten@ietf.org
Message-ID: <20140411001759.3d89cfb5@latte.josefsson.org>
In-Reply-To: <20140312162849.152e924b@latte.josefsson.org>
References: <RT-Ticket-748877@icann.org> <5319DE8B.1030202@att.com> <rt-4.0.8-12541-1394569374-953.748877-9-0@icann.org> <20140312162849.152e924b@latte.josefsson.org>
X-Mailer: Claws Mail 3.8.1 (GTK+ 2.24.10; x86_64-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: clamav-milter 0.98.1 at duva.sjd.se
X-Virus-Status: Clean
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/FlLKEdTPusTaUuRPyJlWMYlIXBc
Subject: Re: [kitten] [IANA #748877] please review SASL-SCRAM-256
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Apr 2014 22:18:17 -0000

Hi again,

I haven't seen anyone disagree with my interpretation that the
registration policy for new SCRAM-* mechanisms are "IETF Review", which
requires an RFC.  Therefor, I will suggest to IANA that they turn down
the registration request until that has been fulfilled.

Personally, I see nothing wrong with registering this, given that a
GSS-API OID is allocated at the same time.

/Simon

You wrote:

> Dear all,
> 
> We have received a request to register the SCRAM-SHA-256 and
> SCRAM-SHA-256-PLUS mechanism.  According to my understanding of what
> RFC 5802 section 10 says, the registration process is "IETF Review"
> http://tools.ietf.org/html/rfc5226#page-11 which requires an RFC, but
> I may be mistaken.  Anyway, suggestions on how to deal with the
> registration request is appreciated.
> 
> Having a SCRAM with SHA-256 seems like a fairly non-controversial
> thing to me.  There are interop aspects though, and the utility of
> defining a lot of variants could be debated.  I would like to see a
> GSS-API OID registered at the same time for any new SCRAM-SHA-* family
> member, but it seems we forgot to write a policy to make sure that
> happens.  Other thoughts?
> 
> /Simon
> 
> You wrote:
> 
> > Dear Simon,
> > 
> > IANA has received a request from Tony Hansen (tony@att.com) for two
> > new registrations in the SASL Mechanisms registry at
> > http://www.iana.org/assignments/sasl-mechanisms. 
> > 
> > Please let us know when the two-week review period on sasl@ietf.org
> > is complete.
> > 
> > thanks,
> > 
> > Amanda Baber
> > IANA Request Specialist
> > ICANN
> > 
> > ===
> > 
> > IANA, please register the following:
> > 
> > To: iana@iana.org
> > Subject: Registration of a new SASL mechanism SCRAM-SHA-256
> > 
> > SASL mechanism name (or prefix for the family): SCRAM-SHA-256
> > Security considerations: Section 7 of [RFC5802]
> > Published specification (optional, recommended): [RFC5802]
> > Person & email address to contact for further information:
> > IETF SASL WG <kitten@ietf.org>
> > Intended usage: COMMON
> > Owner/Change controller: IESG <iesg@ietf.org>
> > Note:
> > 
> > To: iana@iana.org
> > Subject: Registration of a new SASL mechanism SCRAM-SHA-256-PLUS
> > 
> > SASL mechanism name (or prefix for the family): SCRAM-SHA-256-PLUS
> > Security considerations: Section 7 of [RFC5802]
> > Published specification (optional, recommended): [RFC5802]
> > Person & email address to contact for further information:
> > IETF SASL WG <kitten@ietf.org>
> > Intended usage: COMMON
> > Owner/Change controller: IESG <iesg@ietf.org>
> > Note:
> > 
>